SecretSifter: Live Credentials & Secrets Scanner
2 ratings
)Overview
Detects secrets, API keys, and tokens in JS, JSON, XML, and HTML at runtime
SecretSifter is a runtime secrets scanner built for penetration testers, bug bounty hunters, and security engineers. It automatically intercepts and scans network traffic in the active tab — JavaScript files, JSON API responses, XML responses, HTML pages, and WebSocket frames — and flags exposed secrets such as: • API keys, Bearer tokens and JWT secrets • Passwords and credentials in response bodies KEY FEATURES • T1 / T2 / T3 confidence tiers to separate real findings from noise • WebSocket scanning — intercepts both incoming and outgoing WS frames • CDN blocklist — skip known third-party libraries and analytics scripts automatically • Suppressed key names — silence app-specific noise with one click • Full findings report with severity badges (Critical / High / Medium / Low) • Export findings to JSON, CSV, or HTML report • Export scanned URL list (JS, JSON, HTML, XML, requests, WebSocket) • DevTools panel + popup — works however you prefer • Privacy-first — all findings stored locally in your browser; the only external call is an optional Google Maps API key validation probe sent directly to Google DESIGNED FOR SECURITY PROFESSIONALS Scanning is opt-in per tab. No accounts, no telemetry, no developer-controlled servers.
5 out of 52 ratings
Details
- Version1.1.0
- UpdatedMarch 26, 2026
- Offered bygorijala2k16
- Size76.21KiB
- LanguagesEnglish (United States)
- Developer
Email
gorijala2k16@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
SecretSifter: Live Credentials & Secrets Scanner has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
SecretSifter: Live Credentials & Secrets Scanner handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes